Threats Tagged 'cwe-20'
View all threats tagged with 'cwe-20'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-20'
Click on any threat for detailed analysis and mitigation recommendations
Joplin versions prior to 3.6.15 and between 3.7.0 and before 3.7.2 contain an improper input validation vulnerability. This flaw allows an attacker with write access to a sync target or shared notebook to create or overwrite files outside the intended resource directory by exploiting path traversal in resource metadata. The issue is resolved in versions 3.6.15 and 3.7.2. Join the discussion | CVE Database V5 | 09/21/2026, 20:50:28 UTC Added: 09/21/2026, 21:02:12 UTC |
Envoy versions prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1 contain a vulnerability in the ext_authz filter where improper input validation of path-less CONNECT requests can cause a null pointer dereference. This allows an unauthenticated downstream client to crash the Envoy process when query-parameter mutation is configured in the authorization response. The issue is fixed in the specified versions. Join the discussion | CVE Database V5 | 09/21/2026, 19:47:54 UTC Added: 09/21/2026, 20:02:20 UTC |
Envoy proxy versions prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1 contain an improper input validation vulnerability in the HTTP RBAC component. This flaw allows a downstream client to bypass negative RBAC policies by exploiting differences in how opaque header bytes are evaluated with RE2's UTF-8 semantics, potentially permitting unauthorized requests to reach routes intended to be denied. The issue is fixed in the specified patched versions. Join the discussion | CVE Database V5 | 09/21/2026, 19:37:20 UTC Added: 09/21/2026, 19:47:18 UTC |
Missing Authorization in the IOCTL handlers of the wsdkd.sys kernel drivers in Watchdog WatchDog Antivirus 1.8.640 (driver versions 1.3.0.0 and earlier) on Microsoft Windows allows local, low-privileged attackers to delete arbitrary files with SYSTEM privileges, bypassing NTFS access controls and potentially disabling security products or destabilizing the operating system, via crafted IOCTL requests sent to the \Device\wsdk device. Join the discussion | CVE Database V5 | 09/20/2026, 12:02:34 UTC Added: 09/20/2026, 12:32:05 UTC |
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing to invoke Ghostscript, allowing embedded PostScript to operate in the shared temporary directory. An attacker can combine that behavior with a race involving GnuPG configuration files in temporary subdirectories to cause GnuPG to copy attacker-controlled Python code into the application code directory. The injected code executes with the privileges of the SysReptor application process after a worker restart. The Community edition is not affected. Version 2026.58 contains a partial mitigation, and this issue is fully fixed in version 2026.61. Join the discussion | CVE Database V5 | 09/18/2026, 17:47:02 UTC Added: 09/18/2026, 18:02:20 UTC |
Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, the Tenant update validation in internal/webhook/tenant/validation/forbidden_annotations_regex.go compiles ForbiddenLabels.Regex for both the labels and annotations checks instead of validating ForbiddenAnnotations.Regex. An administrator who can update a Tenant can therefore persist a malformed ForbiddenAnnotations.Regex while leaving the labels expression valid. Namespace creation or update later passes the stored expression through pkg/api/forbidden_list.go, where regexp.MustCompile can panic during forbidden metadata validation and deny namespace operations for the affected tenant. This issue is fixed in version 0.13.7. Join the discussion | CVE Database V5 | 09/18/2026, 16:26:18 UTC Added: 09/18/2026, 16:32:08 UTC |
A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policies in rare circumstances. Join the discussion | CVE Database V5 | 09/18/2026, 14:01:10 UTC Added: 09/18/2026, 14:32:19 UTC |
The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including, 1.23.0 via the `my_profile_update()` function. This is due to the function performing no nonce verification, no capability check, and no allowlist validation on the meta key supplied via the `acf-photo-gallery-groups` POST parameter before passing both the meta key and its corresponding value directly to `update_user_meta()`. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary user meta values, though privilege escalation is not possible. Join the discussion | CVE Database V5 | 09/18/2026, 07:40:02 UTC Added: 09/18/2026, 07:47:18 UTC |
0 ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication. Join the discussion | CVE Database V5 | 09/18/2026, 05:37:32 UTC Added: 09/18/2026, 05:47:09 UTC |
Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance. From 1.15.0 until 1.22.8, Browsertrix improperly sanitizes Git URLs specified as Custom Behaviors, allowing command injection through /api/orgs/*/crawlconfigs/validate/custom-behavior. A user with crawler or administrator permission on the specific instance can supply a crafted Git URL that executes arbitrary operating-system commands in the backend pod. Open registration or hosted free-trial access can make the required role broadly obtainable. Successful exploitation can expose, modify, or delete application database records, archived items, browser profiles, storage data, proxy credentials, and other configured service data. This issue is fixed in version 1.22.8. Join the discussion | CVE Database V5 | 09/17/2026, 20:15:14 UTC Added: 09/17/2026, 20:47:37 UTC |
Showing 1 to 10 of 1195 results